脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
脆弱性説明
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local attackers to escalate privileges. Attackers can place a malicious executable in the Program Files directory path to be executed with LocalSystem privileges when the service starts automatically.
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
脆弱性タイプ
未经引用的搜索路径或元素
脆弱性タイトル
Brother SAPSprint 权限许可和访问控制问题漏洞
脆弱性説明
Brother SAPSprint是美国Brother公司的一款主要用于 Windows 环境下的 SAP 打印路由和假脱机服务端程序。 Brother SAPSprint 7.60版本存在权限许可和访问控制问题漏洞,该漏洞源于未加引号的服务路径问题,可能导致本地攻击者在服务自动启动时通过将恶意可执行文件放置在Program Files目录路径中提升权限。
CVSS情報
N/A
脆弱性タイプ
N/A